2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-24443MEDIUM6.5An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface ...
CVE-2024-45478MEDIUM4.8Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended ...
CVE-2024-24445MEDIUM6.5OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protoc...
CVE-2024-57545MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_nu...
CVE-2024-57544MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is...
CVE-2024-57543MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) ...
CVE-2024-57541MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_s...
CVE-2024-57540MEDIUM6.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is cop...
CVE-2024-57538MEDIUM6.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_prot...
CVE-2024-57537MEDIUM6.3Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copie...
CVE-2024-57360MEDIUM5.5https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: ...
CVE-2024-55958MEDIUM4.8Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and...
CVE-2024-48392MEDIUM5.4OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into u...
CVE-2024-21245MEDIUM5.4Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). ...
CVE-2024-55504MEDIUM5.5An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially ...
CVE-2024-51417MEDIUM6.4An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static prop...
CVE-2024-54795MEDIUM5.4SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the works...
CVE-2024-54792MEDIUM6.1A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An ...
CVE-2024-56990MEDIUM4.5PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin...
CVE-2024-56998MEDIUM4.2PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the param...
CVE-2024-56997MEDIUM4.2PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Emai...
CVE-2024-56277MEDIUM5.3Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: fr...
CVE-2024-57946MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: virtio-blk: don't keep queue frozen during system s...
CVE-2024-57944MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: Add NULL check in ads1298_ini...
CVE-2024-57942MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfs: Fix ceph copy to cache on write-begin At th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now